Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 da0642d852f84c19…

MALICIOUS

Office (OOXML)

9.5 KB Authoring application: 14.0300 First seen: 2022-07-02
MD5: c6b0c69e86c849025cffda0775db2828 SHA-1: 96a72cf5185b12834bbf206e24b556e58474bf46 SHA-256: da0642d852f84c19d192a3c908691a63ae7a089b6cc3cedec6ad25c696d4c8c7
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.